From my observation, they didn't steal the coins,, almost everything went back to the imput address as change, they were just sending a message across to inform them of their coins being vulnerable and maybe seeking an offer to fix it the bug for them when contacted. They're good guys. It's something positive as PrivacyG noted.
The input address might belong to the hacker. It was funded by an address that received 3,996 BTC from a Liquid peg-out in this transaction
https://mempool.space/tx/8db751a650ae2f12006b7e8c69a75e4df360e8afd6b9e05ae0b9fa6458a7b140It was obvious that this wasnt white hackers, even though some guys here were hoping the situation wasnt negative. I believe that white hackers would never sign a transaction in op_return, since such a large transaction would be noticed by on‑chain analysts anyway. And white hackers always end up sharing information about their victories over hackers on social media. In our case, this signature was a naive attempt to dispel suspicion.
Meanwhile, the Liquid white hats claim they will return most of the 4,000 BTC as soon as the Liquid network bug is fixed. A real chat began on the blockchain between the hacker and Blockstream:
The hackers were negotiating with Blockstream via OP_RETURN messages and encrypted PGP text
- block 965,822: the Blockstream address sent 1,000 satoshis with the text Please contact security at blockstream dot com.
- block 965,865: an encrypted message addressed to the holders own key, with a detached PGP signature. This signature is verified using the key published at
blockstream.com/pgp.txt- block 965,869: the hacker responded by spending the funds on themselves, but sending 1,000 satoshis to the federations wallet for linking, along with the text: sending most back to [the federation address], is that ok.
- Block 965,875: substantive response. Another self‑transaction, with 1,000 satoshis sent to the federation, and OP_RETURN: Please fix the bug first. The chain is at risk at the latest commit right now. Make sure every node is patched. Then we will transfer the money back safely after confirming the fix.
The technical details follow in the form of a PGP message encrypted with the published Blockstream key, so only Blockstream can read it.
What a way to comunicate....
